First published: Thu May 09 2019(Updated: )
Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Serendipity (S9Y) Freetag Event | <2.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11870 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2019-11870, upgrade Serendipity to version 2.1.5 or later, which addresses the XSS vulnerability.
CVE-2019-11870 can be exploited to perform cross-site scripting attacks through manipulated EXIF data.
CVE-2019-11870 affects all versions of Serendipity before 2.1.5.
The vulnerability in CVE-2019-11870 affects the Editor Preview feature and Media Library feature in Serendipity.